Privacy Agreement

BMALL Personal Information Protection Policy

Update Date: [March 27, 2022]

 

Dear Users ("You"),

 

Welcome to Bmall (the official website of Bmall [www.bmall.io], hereinafter referred to as "the platform"), which is operated by Hong Kong Bmall Technology Co., Ltd. (hereinafter referred to as "we"). When you use this platform service, we may collect and use your relevant personal information. We know the importance of personal information to you and will do our best to protect your personal information security. We will protect your personal information in accordance with national laws and regulations and abide by the principles of consistent rights and responsibilities, clear purpose, optional consent, minimum necessary, openness and transparency, security and subject participation. In order to help you understand what personal information we collect from you and how we use, save, share and transfer such information when you use the Platform, we hereby formulate the Personal Information Protection Policy of Bmall (hereinafter referred to as the "Policy"). Please read this policy carefully especially the contents in bold. If you have any questions, comments or suggestions, you may contact us through the contact information in Section 9 of this Policy.

This policy will help you understand the following:

 

1. How do we collect and use your personal information

 

2. How do we use cookies and related technologies

 

3. How do we share, transfer and publicly disclose your personal information

 

4. Your right to personal information

 

5. How do we protect your personal information

 

6. How do we store your personal information

 

7. Protection of personal information of minors

 

8. Policy updates

 

9. How to contact us

1.       How do we collect and use your personal Information

1.1.      Help you register your account

In order to create your account on the platform, you need to provide us with your mobile phone number, avatar, nickname and gender. If you refuse to provide this information, we will not be able to create an account for you.

1.2.      Help you complete real-name verification

In accordance with relevant anti-money laundering requirements, in order to help you complete the real-name verification, you need to provide us with your real name and ID photo, and we need to collect your facial recognition information through the photos you take and upload. If you refuse to provide the above information, you will not be able to purchase goods on the platform.

1.3.      Process your purchase order

Information related to purchase orders can be used to process purchase orders and related after-sales services. For example, in order to deliver goods to you and provide after-sales services, we need you to fill in the consignee's address, name and mobile phone number, and may share such information with third-party storage, logistics and service providers. When you make payment, we need to collect your order number, payment serial number, order amount and payment method. Your order number, order amount and payment method need to be shared with the third-party payment company. In order to invoice and send invoices to you, your name and order number need to be shared with the tax authority, and in order to send invoices to you, your invoice address, name, mobile phone number and postcode need to be submitted to the third-party logistics provider. In order to protect the security of your transactions, we may need to collect your account information, device information, IP address, bank card number, your registered mobile phone number and email address. Your IP address, bank card number, registered mobile phone number and email address will be anonymized. In order to facilitate after-sales service, we need to record the equipment information you purchase

1.4.      Show you product or service information

We will collect and use your device information, software information, IP address and service log information when you access and use the Platform in order to better display product or service information to you, provide better service and help us ensure the security of the operating environment according to your use of the device.

Device Information: We will collect information about the properties, links, and status of the devices you use when using the products or services.

Software Information: We collect information about the mobile applications and other software you use, including the version number and browser type.

Service log information: We will collect your access to and use of the platform as a service log, including the historical information records you search and view, service fault information, referral website.

1.5.      Help you complete the transaction

1.5.1 When you purchase goods on the platform, we will collect your transaction information, including the type of goods, order number, transaction time and transaction amount, so as to help you successfully complete the transaction and ensure the security of your transaction.

1.5.2 When you choose to bind your bank card for quick payment, you understand and agree that we collect, store and use the information provided by you or authorized third parties for cross-verification and data verification with partner banks or third parties that legally retain your information.

1.5.3 You agree and authorize us to collect the name, ID card type and number, bank card number, bank reserved mobile phone number and other elements you fill in on our card binding page or you authorize the currently logged in third-party platform when you use express payment for the first time and transmit them to your issuer; After the issuer matches and compares the above information with the information you reserved in the bank, you agree and authorize the issuer to return the verification results to us, and establish a binding payment relationship between your bank account, payment account and current platform account.

1.5.4 You authorize and agree that we will record and save the authenticated bank card information (name, id card type and number, bank card number and mobile phone number reserved by the bank) after the real-name authentication of your platform account, and automatically authenticate the bank card bound to your platform account.

1.5.5 In order to complete payment timely and accurately and meet regulatory requirements such as anti-money laundering, you understand and agree that we need to record real-name authentication information, bank card information and transaction information of your platform account for using the Fast Payment service. During the period of your use of the Service and after the termination of the Service, you understand and agree that we retain the relevant data generated during your use of the Service for as long as required by relevant laws, regulations or regulations.

1.5.6 You know and authorize us to summarize and desensitize your bound bank card numbers and card types in the list of our card center and associate them with your platform account.

1.5.7 We may, in conjunction with banks, card organizations, our affiliates or creators, provide you with payment preference services or push information or notifications related to commodity/payment preference services, such as payment preference for the first time, quick payment preference immediate reduction, full reduction, point exchange, point redemption, etc. You agree to authorize us to recommend preferential activities based on your card binding time, active usage, points, payment order information, etc. We guarantee that such information will only be used to provide you with relevant marketing services or account reconciliation under the business scenario of the platform, and will not be disclosed to or allowed to be used by any third party. If you choose to use a bank card with coupons when making payment, it will be deemed that you have agreed to participate in the joint marketing activities between the bank and us. If you do not agree to participate in the above activities, you can choose to unsubscribe or contact our customer service phone feedback.

1.6.      Communicate with you

To ensure that you can receive notifications from us, you need to provide us with your email address. If you refuse to provide email information, you may not be able to receive the message notification sent by us.


When you take the initiative to contact us, we need you to provide necessary personal information to verify your user identity.


We may send you notifications if we detect suspicious activity (such as trying to log in to your account from a different location than usual) or violations of rules or other infringements.


We may keep records of communication, correspondence or phone calls with you, which may contain your account information, order information, contact information or other personal information.

1.7.      Questionnaire survey

In order to better provide services and improve service quality, we may invite you to participate in the questionnaire survey about our products and services and collect the questionnaire response information you send to us during the survey.

1.8.      Statistical analysis

In order to improve our services, we will conduct research, statistics, analysis and prediction after anonymizing or de-labeling your personal information, improve our products and services on the basis of statistical data, design, develop and promote new products and services.

1.9.      Additional consent

Please understand that due to the change of business strategy, the functions of our products and / or services may also be changed and developed. If we want to use your personal Information for other purposes not specified in this Policy, or use the collected personal Information for other purposes for specific purposes, we will obtain your consent again.

1.10.   Exceptions to Authorized Consent

According to relevant laws and regulations, we do not need your authorization and consent to collect and use your personal information under the following circumstances:

(1) Relevant to the performance of our obligations under laws and regulations;

 

(2) Directly related to national security and national defense security;

 

(3) Directly related to public safety, public health and major public interests;

 

(4) Directly related to judicial or administrative law enforcement such as criminal investigation, prosecution, trial and judgment execution;

 

(5) For the purpose of safeguarding your or other personal life, property and other major legitimate rights and interests, but it is difficult to obtain my consent;

 

(6) Your personal information disclosed to the public by yourself;

 

(7) Collecting personal information from legally disclosed information, such as legal news reports, government information disclosure and other channels;

 

(8) Necessary for signing and performing relevant agreements or other written documents with you;

 

(9) It is necessary to maintain the safe and stable operation of the provided products and / or services, such as finding and handling the faults of products and / or services;

 

(10) Other circumstances stipulated by laws and regulations.

1.11.   Stop operation

If we stop operating this platform or some of its services, we will stop collecting your personal information in time, notify you of the notice of stopping operation in the form of delivery or announcement one by one, and delete or anonymize the personal information related to the closed business held by us.

2.       How do we use cookies and related technologies

In order to ensure the normal operation of the website and make your access experience easier, we will store a small data file named cookie on your computer or mobile device. Cookies usually contain identifiers, site names, and numbers and characters. With the help of cookies, the website can store your preferences and other data, provide you with more personalized user experience and services, and improve our services and user experience. We will not use cookies for any purpose other than those stated in this policy. You can manage or delete cookies according to your preferences. For details, see AboutCookies.org. You can clear all cookies saved on your computer. Most web browsers have the function of blocking cookies. However, if you do so, it may affect your safe access to our website in some cases, and you need to change the user settings each time you visit our website.

3.       How do we share, transfer and publicly disclose your personal information

3.1.      Share

3.1.1.     We will not share your personal information with any company, organization or individual other than Hong Kong Bitao Technology Co., Ltd., except for the following circumstances:

1Sharing when express consent: After obtaining your explicit consent, we will share your personal information with other parties. The scope and purpose of sharing personal information will be explained and displayed when obtaining your authorization and consent;

 

(2) Sharing under legal circumstances: we may share your personal information in accordance with laws and regulations or the mandatory requirements of the competent government departments. The scope of sharing personal information will be determined according to laws and regulations and the requirements of relevant administrative or judicial departments;

 

(3) Sharing with our affiliates: your personal information may be shared with our affiliates. We will only share necessary personal information and are bound by the purposes stated in this policy. We will require the affiliated companies that share your personal information with us to store and process your personal information in the manner agreed in this policy. Before sharing information, we will conduct reasonable commercial review, evaluate the legitimacy, legitimacy and necessity of sharing your personal information, and urge relevant parties to deal with your information in accordance with legal provisions and regulatory requirements. If our affiliated companies want to change the purpose of processing personal information, they will ask for your authorization and consent again;

 

(4) Sharing with partners: only for the purpose stated in this policy, we may share your account information, equipment information and location information with third parties such as partners, so that we entrust authorized partners to provide you with some services. We will share your information only for the legal, legitimate, necessary, specific and clear purpose stated in this policy, Authorized partners can only access the information they need to realize the services, and we will require them not to use this information for any other purpose through an agreement. Our partners include suppliers of infrastructure technology services, payment services, data processing and video technology services. And in order to protect the property security of you and other users, prevent fraud and other illegal activities and reduce credit risk, we may exchange information with other companies and organizations, but we will not sell, rent, share or disclose your personal information in other ways for profit in violation of the commitments made in this policy. For companies, organizations and individuals with whom we share personal information, we will sign strict confidentiality agreements with them and require them to handle personal information in accordance with our instructions, this policy and any other relevant confidentiality and security measures. We will also ensure that the collection and use of personal information meet the requirements of laws, regulations and agreements through technical testing, security audit and other means;

 

(5) In order to achieve the purpose stated in this policy, some third-party plug-ins (such as software tool development kit (SDK) and application program interface (API)) will be connected to our products or services to support the specific functions of our products or services. Therefore, we need to share or transmit specific personal information with these third parties, and these third-party SDKs may also collect personal information from you directly through our app. If you want to know the details of the third-party plug-ins, please ask us for the SDK directory. We will regularly or irregularly conduct technical testing and behavior audit on such partners or service providers, and require them to abide by the cooperation agreement to ensure that they collect and use data according to law, regulations and agreements to the greatest extent.

3.2.      Assignment

We will not transfer your personal information to any company, organization or individual, except for the following circumstances:

 

(1) Obtain your explicit consent or authorization in advance;

 

(2) In the event of acquisition, merger or bankruptcy liquidation, if the transfer of personal information is involved, we will require the new company or organization that holds your personal information to continue to be bound by this Policy; otherwise, we will require the company, organization or individual to seek authorization from you again.

3.3.      Public disclosure

We will only publicly disclose your personal information under the following circumstances:

1After obtaining your explicit consent;

2If we are required to provide your personal information in accordance with laws, regulations, mandatory administrative law enforcement or judicial requirements, we may publicly disclose your personal information based on the type and disclosure method of personal information required. Subject to compliance with laws and regulations, when we receive such disclosure requests, we will require the issuance of corresponding legal documents, such as subpoenas or letters of investigation.

3.4.      Exceptions to prior authorization and consent for sharing, transferring and publicly disclosing personal information

According to relevant laws and regulations, you do not need to obtain your authorization and consent in advance for sharing, transferring and public disclosure of your personal information under the following circumstances:

(1) Related to our performance of our obligations under laws and regulations;

 

(2) Directly related to national security and national defense security;

 

(3) Directly related to public safety, public health and major public interests;

 

(4) Directly related to criminal investigation, prosecution, trial and judgment execution;

 

(5) For the purpose of safeguarding your or other personal life, property and other major legitimate rights and interests, but it is difficult to obtain my authorization and consent;

 

(6) Your personal information disclosed to the public by yourself;

 

(7) Collecting personal information from legally disclosed information, such as legal news reports, government information disclosure and other channels.

4.       Your right to Personal Information

According to China's relevant laws, regulations and standards, and you shall have the right to query, copy, correction, delete your personal information, request us to explain your personal information processing rules, and change you agreed to the scope of authorization, cancel your account, and within the scope of the laws and regulations, and request to transfer your personal information to its designated personal information processing. We will ensure that you exercise the above rights with regard to your personal information. During your use of the Platform, you may exercise your rights to your personal information in the following ways.

4.1.      Access your personal information

You have the right to access your personal information. You can access it in the following ways: click the upper right corner of the home page of this platform to enter the personal center, and access your mobile phone number, order and other information in the personal home page.

4.2.      Correct your personal information

You have the right to correct your personal information. In order to facilitate you to correct your personal information, we provide you with two ways: Online self-correction and application for correction.

4.2.1.     For some of your personal information, you can correct it by yourself through the way in "access your personal information".

4.2.2.     You can also ask us for help to correct your personal information through the contact information provided in Section 9 of this policy.

4.3.      Delete your personal information

4.3.1.     In the following cases, you have the right to ask us to delete your personal information through the contact information provided in Section 9 of this policy, and we will reply within a reasonable time after verifying your identity. When we delete your personal information from the server, we may not delete the corresponding data from the backup system immediately, but we will delete the information when the backup is updated.

(1) If we deal with personal information in violation of laws and regulations;

 

(2) If we collect or use your personal Information without your consent;

 

(3) If our processing of personal information violates our agreement with you;

 

(4) If you no longer use our products or services, or you cancel your account;

 

(5) If we no longer provide you with products or services.

4.4.      Change the scope of your authorization and consent

You may change the scope of consent or withdraw your authorization by adding or deleting information, changing privacy settings or turning on or off the corresponding functions of your device, and contacting us in the way specified in Article 9 of this policy.

When you withdraw your authorization, we will no longer process the corresponding personal information. However, your decision to withdraw your authorization will not affect our previous personal information processing based on your authorization.

4.5.      Cancel your account

You can contact us through the contact information provided in Section 9 of this Policy to assist you in cancelling your account.

 

After you cancel your account, we will stop providing you with products or services, and delete your personal information or anonymize it according to the requirements of applicable laws.

4.6.      Other personal information rights

You can contact us through the contact information provided in Section 9 of this policy, copy your personal information according to law, ask us to explain the processing rules of your personal information, and request to transfer your personal information to the designated personal information processor within the scope of laws and regulations.

4.7.      Respond to your above request

For security, you may need to provide a written request or otherwise prove your identity. We may ask you to verify your identity before processing your request.

 

In principle, we will not charge for your reasonable request, but we will charge a certain cost for repeated requests that exceed the reasonable limit according to the situation. We may reject requests that are unreasonably repeated, require too many technical means (e.g., need to develop new systems or fundamentally change current practices), pose a risk to the legitimate rights and interests of others, or are very impractical (e.g., involve information stored on backup tapes).

 

Under the following circumstances, we will not be able to respond to your request in accordance with the requirements of laws and regulations:

 

(1) Related to our performance of our obligations under laws and regulations;

 

(2) Directly related to national security and national defense security;

 

(3) Directly related to public safety, public health and major public interests;

 

(4) Directly related to criminal investigation, prosecution, trial and execution of judgment;

 

(5) There is sufficient evidence to show that the subject of personal information has subjective malice or abuse of rights;

 

(6) For the purpose of safeguarding the life, property and other major legitimate rights and interests of the personal information subject or other individuals, but it is difficult to obtain my authorization and consent;

 

(7) Responding to your request will cause serious damage to the legitimate rights and interests of you or other individuals and organizations;

 

(8) Involving trade secrets.

5.       How do we protect your personal information?

5.1.      Safety protection measures

We have used industry standard security measures to protect the personal information provided by you from unauthorized access, public disclosure, use, modification, damage or loss. We will take all reasonable and feasible measures to protect your personal information. For example, when exchanging data between your browser and our services, it is protected by SSL encryption; We also provide HTTPS safe browsing for this platform; We will use encryption technology to ensure the confidentiality of data; We will use trusted protection mechanisms to prevent malicious attacks on data; We will deploy access control mechanisms to ensure that only authorized personnel can access personal information.

5.2.      Encrypted transmission and storage of personal sensitive information

We will encrypt and store identifiable personal sensitive information. The encryption strength meets the security requirements to ensure the confidentiality of the data. Please understand that the Internet is not an absolutely secure environment, and email, instant messaging and communication with other users are not encrypted. Therefore, we strongly recommend that you do not send sensitive personal information through such methods.

5.3.      Employee safety training

We will hold security and privacy protection training courses from time to time to strengthen employees' awareness of the importance of protecting personal information.

5.4.      Information security incident response

We will try our best to ensure the security of any information you send us, but the Internet environment is not 100% secure. If our physical, technical or management protection facilities are damaged, resulting in unauthorized access, public disclosure, tampering or destruction of information, and damage to your legitimate rights and interests, we will bear corresponding legal responsibilities. After the unfortunate personal information security incident, we will timely inform you of the basic situation and possible impact of the security incident, the disposal measures we have taken or will take, the suggestions you can independently prevent and reduce the risk, and the remedial measures for you in accordance with the requirements of laws and regulations. We will timely inform you of the relevant information of the event by email, letter, telephone, push notification, etc. when it is difficult to inform the personal information subject one by one, we will take a reasonable and effective way to make an announcement. At the same time, we will also actively report the disposal of personal information security incidents in accordance with the requirements of regulatory authorities.

6.       How do we store your personal information

6.1. Storage location

We abide by laws and regulations, and the personal information collected and generated during our operations in China will be stored in China.

6.2. Storage period

Generally speaking, we will only retain your personal information for the shortest time necessary to achieve the purpose. After the time limit is exceeded, we will delete or anonymize your personal information, unless otherwise stipulated by laws and regulations or otherwise authorized by you.

If we stop operating the Platform and related services, we will stop collecting your personal information in a timely manner, notify you to stop operations in the form of a notice, and delete or anonymize our stored personal information.

7.       Protection of minors' personal information

We take the protection of minors' personal information very seriously. We do not knowingly collect personal information from minors, and no part of our products and services are intended for minors. If you are a minor under the age of 18, please do not use or access our products and services in any way. When we become aware that we have unintentionally collected personal information from minors, we delete it or take other appropriate action in accordance with applicable laws and regulations.

8.       Update of this policy

In order to provide you with better services, our services and technologies will continue to be optimized and improved, and we will modify this policy at any time according to the update of services and technologies and relevant requirements of laws and regulations. However, we will not limit your rights under this Policy without your express consent.

For major changes, we will also provide more prominent notices and publicize them on the platform. Material changes referred to in this Policy include, but are not limited to:

(1) Major changes have taken place in our service model. For example, the purpose of processing personal information, the type of processing personal information, the way of using personal information, etc.

(2) We have undergone major changes in ownership structure and organizational structure. Such as business adjustment, bankruptcy merger and acquisition caused by the owner change;

(3) The main object of personal information sharing, transfer or public disclosure changes;

(4) Your rights to personal information and the way to exercise them change significantly;

(5) Our responsible departments, contact methods and complaint channels for handling personal information security change;

(6) The personal information security impact assessment report indicates that there is a high risk;

(7) Other important or may seriously affect your personal rights and interests.

Any changes will put your satisfaction first. We encourage you to check our personal information protection policy every time you visit our platform.

9.       How to contact us

Hong Kong Bmall Technology Co., Ltd. is the main operator of this platform and the controller of your personal information. The registration and contact address [6506a, 65 / F, SEG Plaza, 1002 Huaqiang North Street, Futian District, Shenzhen City].

If you have any inquiries, complaints or suggestions on issues related to personal information protection, or need to query, correct, supplement or withdraw the personal information you have provided to Bmall, you can contact [lawers@bmall.io], and we will review the issues involved as soon as possible and reply within 15 working days after verifying your user identity.

If you are not satisfied with our reply, especially if you think our personal information processing behavior has damaged your legitimate rights and interests, you can also seek a solution by bringing a lawsuit to the people's court with jurisdiction in the place where the defendant resides.